~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to retired/CVE-2014-1525

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
PublicDateAtUSN: 2014-04-29
2
 
Candidate: CVE-2014-1525
3
 
PublicDate: 2014-04-30
4
 
References: 
5
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1525
6
 
 http://www.mozilla.org/security/announce/2014/mfsa2014-39.html
7
 
 https://usn.ubuntu.com/usn/usn-2185-1
8
 
Description:
9
 
 The mozilla::dom::TextTrack::AddCue function in Mozilla Firefox before 29.0
10
 
 and SeaMonkey before 2.26 does not properly perform garbage collection for
11
 
 Text Track Manager variables, which allows remote attackers to execute
12
 
 arbitrary code or cause a denial of service (use-after-free and heap memory
13
 
 corruption) via a crafted VIDEO element in an HTML document.
14
 
Ubuntu-Description: 
15
 
Notes: 
16
 
Bugs: 
17
 
Priority: medium
18
 
Discovered-by:
19
 
Assigned-to: chrisccoulson
20
 
 
21
 
Patches_firefox:
22
 
upstream_firefox: released (29.0)
23
 
lucid_firefox: ignored (reached end-of-life)
24
 
precise_firefox: released (29.0+build1-0ubuntu0.12.04.2)
25
 
quantal_firefox: released (29.0+build1-0ubuntu0.12.10.3)
26
 
saucy_firefox: released (29.0+build1-0ubuntu0.13.10.3)
27
 
trusty_firefox: released (29.0+build1-0ubuntu0.14.04.2)
28
 
devel_firefox: not-affected (29.0+build1-0ubuntu0.14.04.2)